๐Ÿ” JWT Generator

Algorithm: HS256 (HMAC-SHA256), fixed

Generated JWT
Enter a secret key

Enter a JSON payload and a secret key to generate an HS256 (HMAC-SHA256) signed JWT (JSON Web Token) on the spot. The signature is computed using the browser's built-in Web Crypto API.

How to use

  1. Edit the payload JSON (set any claims you want, like sub, name, iat).
  2. Enter the secret key to sign with.
  3. The generated JWT appears automatically โ€” click "Copy" to copy it to your clipboard.

How the calculation works

A JWT (JSON Web Token, RFC 7519) carries signed claims such as login information. It is three parts โ€” header.payload.signature โ€” joined by dots. This tool signs a JWT with HS256 from the payload JSON and secret you enter. 1. Base64URL-encode the header {"alg":"HS256","typ":"JWT"} 2. Serialise the payload JSON without whitespace and Base64URL-encode it 3. Sign "header.payload" with HMAC-SHA256 using the secret, and Base64URL-encode the signature 4. Join the three parts with dots The signature is computed with the browser's Web Crypto API. A receiver recomputes it with the same secret; if it matches, the token has not been tampered with.

Worked example

Payload: {"sub":"1234567890","name":"John Doe","iat":1516239022} Secret: your-256-bit-secret Result (identical to the jwt.io sample) eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiaWF0IjoxNTE2MjM5MDIyfQ.SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c

Things to be aware of

  • A JWT payload is not encrypted; anyone can Base64URL-decode and read it. Never put passwords or other secrets in it.
  • Use a long random secret for HS256 (32 bytes or more). Short secrets can be brute-forced.
  • An expiry claim (exp) limits the damage if a token leaks. Never enter production secrets into a web tool like this.

FAQ

Where is the signature computed?

Entirely in your browser, using the built-in Web Crypto API (crypto.subtle) to compute the HMAC-SHA256 signature. Your secret key is never sent to a server.

Does this support algorithms other than HS256?

No, the current version only supports HS256 (HMAC-SHA256).

Can I verify the generated JWT is correct?

Yes โ€” paste it into this site's JWT Decoder to check its contents, or verify the signature with an external tool like jwt.io using the same secret key.